for Organizational Transformationand Change Management
NewsletterSubscribe

In regulated industries, the change plan can be part of the compliance record

Where regulators require validation, audit trails and training records, much of what a change team produces becomes compliance evidence. A close reading of the rules shows what they demand and where they stop.

A laboratory bench with racks of labeled sample vials and an open binder of procedures.
Illustration: The Langford Institute.

Europe's guide to good manufacturing practice (GMP) does not stop at telling medicine makers to train their staff. Its chapter on personnel says continuing training should be given, that "its practical effectiveness should be periodically assessed," and that training records should be kept. In the United States, the FDA's electronic records rule, which dates from 1997, requires a determination that people who develop, maintain or use electronic record systems "have the education, training, and experience to perform their assigned tasks."

Set those provisions beside the requirements for validated systems and audit trails, and much of what a change team produces on a regulated system program starts to look like compliance evidence. In this publication's reading, who was trained, on which version of which procedure, before receiving system access, belongs to the quality record. Part 11 makes computer systems, their controls and their "attendant documentation" subject to FDA inspection. None of these rules uses the phrase change management in its organizational sense, so the link is an interpretation, and it has limits.

The vocabulary also holds a trap. In pharmaceutical quality systems, change management already has a defined meaning. ICH Q10, published by the FDA as guidance in 2009, defines it as "a systematic approach to proposing, evaluating, approving, implementing, and reviewing changes" and applies it across a product's lifecycle. It also asks for an evaluation after implementation to confirm that a change achieved its objectives. We see that evaluation as the point where a quality unit's change control and the people side of change meet. In our reading, a new system that staff do not use as designed has not achieved its objectives.

What the life-sciences rules require

In US drug manufacturing, 21 CFR 211.25 requires each person engaged in manufacturing, processing, packing or holding a drug product to have the education, training and experience, or any combination of them, to perform their assigned functions. Training must cover the operations they perform and GMP, including the written procedures that relate to their functions, and GMP training must be given "on a continuing basis and with sufficient frequency" to keep employees familiar with the requirements. The section does not itself mention training records; the EU guide does. Part 11's text adds controls for electronic records, among them validation, secure computer-generated audit trails of operator entries and actions, and revision and change control for systems documentation. Since 2003, however, the FDA has said it will exercise enforcement discretion over those Part 11 validation and audit-trail provisions, relying instead on the underlying predicate rules, while continuing to enforce the training determination.

Annex 11 of the EU GMP guide, on computerized systems, in operation since June 30, 2011, asks that personnel have "appropriate qualifications, level of access and defined responsibilities," that audit trails be considered on the basis of risk and regularly reviewed, and that changes follow a defined procedure. In our reading, its statement of principle reads like a brief for a change team: where a computerized system replaces a manual operation, product quality, process control and quality assurance should not decrease. A revision drafted by the European Medicines Agency's inspectors' working group and PIC/S went to stakeholder consultation from July 7 to October 7, 2025. The draft says everyone involved with such systems should have "adequate system specific training," but the Commission's EudraLex listing still shows the 2011 text as current.

Two guidance documents shape how much validation evidence is enough. ISPE's GAMP 5 Second Edition, an industry guide published in July 2022, emphasizes critical thinking by experienced subject-matter experts in defining appropriate approaches. The FDA's Computer Software Assurance guidance, issued in draft in September 2022, finalized on September 24, 2025 and reissued on February 3, 2026, sets out a risk-based approach for software used in medical device production and quality management systems. Both are nonbinding.

In our reading, a new system that staff do not use as designed has not achieved its objectives.

Finance and AI

The EU's Digital Operational Resilience Act, which has applied since January 17, 2025, requires most financial entities to build ICT security awareness programs and digital operational resilience training into their staff training as compulsory modules, "applicable to all employees and to senior management staff." Members of the management body must keep their knowledge of ICT risk up to date, including through specific training on a regular basis.

Article 4 of the EU AI Act, on AI literacy, has applied since February 2, 2025. As first written, it required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and others operating AI systems on their behalf. Regulation (EU) 2026/1744, in force since July 27, 2026, replaced that with a duty to take measures to support the development of AI literacy, adding that the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual." The Commission's guidance says no certificate is needed and that organizations can keep an internal record of training and other initiatives. Article 99, which sets the Act's maximum fines, does not list Article 4 among the obligations it names; member states set penalties for other infringements.

In US banking, the Federal Reserve's 2011 model risk guidance, SR 11-7, was superseded on April 17, 2026 by SR 26-2, issued with the OCC and FDIC. The revised guidance says that "effective model use depends on a clear understanding of a model's limitations." It also states that it sets no enforceable standards, that non-compliance will not result in supervisory criticism, and that generative and agentic AI models fall outside its scope.

The case against, and what to do

The strongest objection is that none of these texts requires an adoption metric or a change plan. They require qualified people, validated systems, controlled changes and records. A training record shows that a session took place, not that anyone works differently, and few of the rules ask whether training worked. The EU guide's effectiveness clause is the clearest exception; the draft Annex 11 would add evaluation of security training, for example through simulated tests. In our view, the direction of travel also favors proportion over paperwork, although the draft Annex 11 is much longer and more detailed than the 2011 text it would replace. The FDA's software assurance guidance, GAMP 5's emphasis on critical thinking, the narrowing of the AI Act's literacy duty, which the amending regulation justifies partly by the compliance burden on smaller enterprises, and US bank supervisors' disclaimer of enforceable standards all point the same way.

A change team that answers regulation with more documents has misread it. The argument for treating the change plan as part of the compliance record survives in a narrower form: the plan should produce the specific evidence the rules already expect, as a by-product of doing the work well.

  • Map each change deliverable to the requirement it supports: role-based training to Part 11 and, in draft, to the revised Annex 11, staff qualifications to the current Annex 11, effectiveness checks to EU GMP Chapter 2, post-implementation review to ICH Q10, management training to DORA, literacy measures to the AI Act.
  • Grant system access only after training on the current version of the procedure is recorded.
  • Judge training effectiveness with operational data, such as deviations, data corrections and audit-trail findings in the months after go-live, aggregated by role rather than used to score individuals.
  • Keep the change artifacts that serve as evidence in the controlled document system, under version control.
  • Bring quality assurance into the change team before cutover.

Sources

Corrections: none to date. If we find an error, we will correct it here with a dated note. Our standards.